Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3035▼ 39 respecto a la semana anterior
Críticas / altas1415▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
601 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.53% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, `HomeplugMessage::setup_payload` trusts `len` after an `assert`; in release builds the check is removed, so oversized SLAC payloads are `memcpy`'d into a ~1497-byte stack buffer, corrupting the stack and enabling remote code execution from… | |
| Analizada | Alta (7.8) | 0.14% | — | Linuxfoundation Everest | 26/3/2026 | 17/6/2026 | EVerest is an EV charging software stack. Prior to version 2026.02.0, an off-by-one check in IsoMux certificate filename handling causes a stack-based buffer overflow when a filename length equals `MAX_FILE_NAME_LENGTH` (100). A crafted filename in the certificate directory can overflow `file_names[idx]`, corrupting… | |
| Analizada | Media (4.3) | 0.26% | — | Linuxfoundation Nats-server | 25/3/2026 | 17/6/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.11.0 and prior to versions 2.11.15 and 2.12.6, a valid client which uses message tracing headers can indicate that the trace messages can be sent to an arbitrary valid subject, including those to which… | |
| Analizada | Media (4.2) | 0.17% | — | Linuxfoundation Nats-server | 25/3/2026 | 17/6/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using mTLS for client identity, with `verify_and_map` to derive a NATS identity from the client certificate's Subject DN, certain patterns of RDN would not be correctly enforced,… | |
| Analizada | Media (5.4) | 0.24% | — | Linuxfoundation Nats-server | 25/3/2026 | 17/6/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, the NATS message header `Nats-Request-Info:` is supposed to be a guarantee of identity by the NATS server, but the stripping of this header from inbound messages was not fully… | |
| Analizada | Media (4.9) | 0.34% | — | Linuxfoundation Nats-server | 25/3/2026 | 17/6/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, users with JetStream admin API access to restore one stream could restore to other stream names, impacting data which should have been protected against them. Versions 2.11.15 and… | |
| Modificada | Media (5.3) | 0.54% | — | Linuxfoundation Nats-server | 25/3/2026 | 9/9/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, if a nats-server is run with static credentials for all clients provided via argv (the command-line), then those credentials are visible to any user who can see the monitoring port, if… | |
| Analizada | Media (5.4) | 0.24% | — | Linuxfoundation Nats-server | 25/3/2026 | 17/6/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server offers a `Nats-Request-Info:` message header, providing information about a request. This is supposed to provide enough information to allow for account/user identification, such that NATS clients could make… | |
| Modificada | Media (5.3) | 1.0% | — | Linuxfoundation Nats-server | 25/3/2026 | 9/9/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a malicious client which can connect to the WebSockets port can cause unbounded memory use in the nats-server before authentication; this requires sending a corresponding amount of… | |
| Modificada | Alta (7.5) | 0.84% | — | Linuxfoundation Nats-server | 25/3/2026 | 9/9/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, a client which can connect to the leafnode port can crash the nats-server with a certain malformed message pre-authentication. Versions 2.11.15 and 2.12.6 contain a fix. As a… | |
| Modificada | Media (6.5) | 0.37% | — | Linuxfoundation Nats-server | 25/3/2026 | 9/9/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, when using ACLs on message subjects, these ACLs were not applied in the `$MQTT.>` namespace, allowing MQTT clients to bypass ACL checks for MQTT subjects. Versions 2.11.15 and 2.12.6… | |
| Modificada | Alta (7.5) | 0.63% | — | Linuxfoundation Nats-server | 25/3/2026 | 9/9/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.15 and 2.12.6, for MQTT deployments using usercodes/passwords: MQTT passwords are incorrectly classified as a non-authenticating identity statement (JWT) and exposed via monitoring endpoints. Versions… | |
| Modificada | Alta (7.5) | 0.97% | — | Linuxfoundation Nats-server | 25/3/2026 | 9/9/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.14 and 2.12.5, if the nats-server has the "leafnode" configuration enabled (not default), then anyone who can connect can crash the nats-server by triggering a panic. This happens pre-authentication… | |
| Modificada | Alta (7.5) | 0.84% | — | Linuxfoundation Nats-server | 25/3/2026 | 9/9/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Starting in version 2.2.0 and prior to versions 2.11.14 and 2.12.5, a missing sanity check on a WebSockets frame could trigger a server panic in the nats-server. This happens before authentication, and so is exposed to… | |
| Analizada | Media (6.5) | 0.28% | — | Linuxfoundation Nats-server | 24/3/2026 | 17/6/2026 | NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. The nats-server provides an MQTT client interface. Prior to versions 2.11.15 and 2.12.5, Sessions and Messages can by hijacked via MQTT Client ID malfeasance. Versions 2.11.15 and 2.12.5 patch the issue. No known… | |
| Modificada | Crítica (9.6) | 0.70% | — | Linuxfoundation Tekton Pipelines | 24/3/2026 | 7/9/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Starting in version 1.0.0 and prior to versions 1.0.1, 1.3.3, 1.6.1, 1.9.2, and 1.10.2, the Tekton Pipelines git resolver is vulnerable to path traversal via the `pathInRepo` parameter. A tenant with permission to create… | |
| Analizada | Crítica (9.4) | 0.57% | — | Linuxfoundation Harbor | 23/3/2026 | 10/8/2026 | Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI. | |
| Analizada | Baja (1.9) | 0.40% | — | Linuxfoundation Pytorch | 22/3/2026 | 17/6/2026 | A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the… | |
| Analizada | Media (6.5) | 0.45% | — | Linuxfoundation Tekton Pipelines | 20/3/2026 | 17/6/2026 | Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Versions 0.60.0 through 1.0.0, 1.1.0 through 1.3.2, 1.4.0 through 1.6.0, 1.7.0 through 1.9.0, 1.10.0, and 1.10.1 have a denial-of-service vulnerability in that allows any user who can create a TaskRun or PipelineRun to crash the… | |
| Modificada | Crítica (9.1) | 0.31% | — | Linuxfoundation Onnx | 18/3/2026 | 15/7/2026 | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism. While the function is designed to warn users when loading… | |
| Analizada | Media (6.5) | 0.41% | — | Linuxfoundation Backstage/plugin-scaffolder-backend | 12/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secrets through the dry-run API response. Secrets are properly redacted in log output but not in all parts of the response… | |
| Modificada | Baja (1.7) | 0.47% | — | Linuxfoundation Backstage | 12/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when auth.experimentalClientIdMetadataDocuments.enabled is set to true. The CIMD metadata fetch validates the initial client_id hostname against… | |
| Analizada | Media (4.7) | 0.23% | — | Linuxfoundation Backstage | 12/3/2026 | 17/6/2026 | Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Instances that have enabled experimental Dynamic Client Registration or Client ID Metadata Documents and configured… | |
| Analizada | Media (4.8) | 0.15% | — | Linuxfoundation Inspektor Gadget | 12/3/2026 | 17/6/2026 | Inspektor Gadget is a set of tools and framework for data collection and system inspection on Kubernetes clusters and Linux hosts using eBPF. Prior to 0.50.1, in a situation where the ring-buffer of a gadget is – incidentally or maliciously – already full, the gadget will silently drop events. The… | |
| Analizada | Media (4.3) | 0.33% | — | Linuxfoundation Kubewarden | 10/3/2026 | 17/6/2026 | Kubewarden is a policy engine for Kubernetes. Kubewarden cluster operators can grant permissions to users to deploy namespaced AdmissionPolicies and AdmissionPolicyGroups in their Namespaces. One of Kubewarden promises is that configured users can deploy namespaced policies in a safe manner, without privilege… |